Back to Internships
Internship

Fam security engineer intern Bengaluru 2026 — on-site, apply on Lever

Fam (previously FamPay)

Active
Location
Bengaluru (on-site, Fam HQ)
Last date
31 Dec 2026
Qualification
Student profile with OWASP Top 10 (web and mobile), Burp Suite / Nmap / similar tools, and ability to read Python, Go, Java or JavaScript. Degree name is not printed.
Age limit
Not printed on the Lever card
Vacancies
Not numbered on the card
Pay / stipend
Competitive stipend printed; rupee amount not printed
Experience
CTF, bug bounty, or HackTheBox / TryHackMe rank expected; no year count printed
Application fee
None printed
Selection
Apply on the Lever card and complete the Fam CTF at ctf.fampay.co

Official Details

Fam security engineer intern Bengaluru 2026 is the live Application Security Engineer Intern card on Fam’s official Lever board. Location printed: Bengaluru, on-site at Fam HQ. Apply on jobs.lever.co/fampay. The card also asks you to finish the challenge at ctf.fampay.co. No advertisement number and no last date are printed. This page was checked on 1 October 2026 while the apply button was still on the card.

What Fam actually does

Fam, previously FamPay, is a private payments company. The card says FamApp is a payments app for people above 11, with UPI and FamCard, and that the company was founded in 2019 by IIT Roorkee alumni. Investors named on the card include Elevation Capital, Y Combinator, Peak XV (Sequoia Capital) India, Venture Highway, Global Founders Capital, and angels including Kunal Shah and Amrish Rao. This is not a government internship and not the Prime Minister’s Internship Scheme.

A private internship means the company writes the rules. There is no gazette, no category roster, and no application fee slab. If someone on WhatsApp asks for a “Fam registration charge”, that is not this card.

What kind of role this Fam security engineer intern Bengaluru 2026 seat is

The title on the card is Security Engineer Intern. The body calls it an Application Security Engineer Intern. Department is Engineering. Type is Full Time. Work mode is On-site. The note on the card says this is an onsite internship at Fam HQ, Bangalore. Duration in weeks or months is not printed. Bond is not printed. A full-time offer after the internship is not printed.

Work printed on the card: vulnerability assessment and penetration testing on web apps, Android/iOS apps and APIs; help integrate SAST/DAST into CI/CD; review source code for SQLi, XSS and IDOR; triage bug-bounty reports; threat modelling with product and engineering; stay current with CVEs and zero-days.

Who should apply — and who should skip

Apply if you can explain the OWASP Top 10 for web and mobile, you have used Burp Suite, Metasploit, Nmap, Postman or similar tools, you can read Python, Go, Java or JavaScript and write small scripts, and you already do CTFs, bug bounties, or ranked practice on HackTheBox or TryHackMe. You must be able to work from the Bengaluru office.

Skip if you want a remote seat, if you only know theory and have never opened Burp, or if you cannot explain a bug to a developer in plain language. Bonus points on the card, not must-haves: AWS or GCP cloud security, a hall-of-fame mention on a company bug bounty, open-source security work. Degree name, CGPA, year of study and age are not printed. Do not invent them.

Dates and fee

Item On the official Lever card
Apply start Not printed. Card was live on 1 October 2026
Last date Not printed. Apply while the Lever apply button is up
Duration Not printed
Fee None printed. Do not pay a third party
Stipend Word used is “competitive stipend”. Rupee figure not printed
Other printed perks Certificate, letter of recommendation, leave policy, Fam merchandise
Extra step Complete https://ctf.fampay.co/

Available positions

1. Security Engineer Intern — competitive stipend, rupee amount not printed Seat count not printed

Eligibility criteria
Hacker mindset with a deep understanding of the OWASP Top 10 (web and mobile) and how to exploit and patch them. Hands-on experience with Burp Suite, Metasploit, Nmap, Postman or similar open-source security tools. Ability to read code in Python, Go, Java or JavaScript and write scripts to automate attacks or defences. Active participation in CTFs, bug bounties, or a rank on HackTheBox or TryHackMe. Ability to explain a complex vulnerability to a developer. On-site at Fam HQ, Bangalore. Bonus: cloud security on AWS or GCP, a hall-of-fame bug-bounty mention, open-source security contributions.

No category-wise vacancy split is printed on this notice.

Total vacancies — not numbered on the card.

Educational qualifications

Post Degree / marks Experience / extras
Security Engineer Intern Degree, branch, year and marks are not printed OWASP Top 10, Burp Suite or similar, readable code in Python/Go/Java/JavaScript, CTF or bounty practice, on-site Bengaluru, CTF challenge link

Selection

  1. Open the official Lever card and apply. The card says AI tools may help review applications, but final hiring decisions are made by humans.
  2. Complete the challenge printed on the card: https://ctf.fampay.co/
  3. Further interview rounds are not printed. Do not treat a coaching-site “3 rounds” claim as official.

How to prepare (free, official)

How to apply without getting played

  1. Open only the Lever URL above. Fam will not ask you to pay to “lock” a slot.
  2. Attach a resume that shows one real CTF write-up, bounty report, or lab rank. The card is looking for that, not a generic “interested in cybersecurity” line.
  3. Finish ctf.fampay.co before you assume the form alone is enough. The card prints both steps.
  4. Save the Lever confirmation. There is no fee receipt because no fee is printed.

FAQs

What is the last date?
Not printed on the Fam Lever card. Apply while the apply button is live. Checked 1 October 2026.

Who can apply?
Someone who can work on-site in Bengaluru, knows OWASP Top 10, has used tools such as Burp Suite, can read Python, Go, Java or JavaScript, and already does CTFs or bounties. Degree line is not printed.

How many vacancies?
Not numbered on the card.

Where do I apply?
jobs.lever.co/fampay, plus the CTF at ctf.fampay.co.

What is the fee?
None printed. Stipend is described as competitive. The rupee amount is not printed, so do not quote a number from a reel.

Can final-year students apply?
The notice does not say final-year. It does not print age, degree or year. On-site Bengaluru and the skill list are the filters that are printed.

internships · jobs · admissions.

Applicant Safety

Always verify notices on the official institutional website. Campus Reality only lists public notifications.

  • Double-check deadlines.
  • Never pay fees through unverified third-party links.
  • Read the official PDF carefully before applying.